T-6004validatedactive
Skill/Plugin Backdoor
Install a backdoored skill or plugin that persists across agent restarts
Tactic
Persistence (Stage 6)
Establish persistent access surviving restarts and session changes
Attack Class
SKILL-FRONTMATTER
Embedding malicious instructions in skill or plugin metadata and description fields
Evidence
validated
Reproduced in controlled lab environment (DVAA) with documented steps.
DVAA Validation
skill-backdoor-install
Honeypot Coverage (AgentPwn)
Queuedsupply-chain
In scope for honeypot observation; trap page or telemetry hook not yet built.
Supply-chain trap page not yet built.
Detection (HackMyAgent)
Live6 live · 0 queued
SKILL-001SKILL-002SKILL-003SKILL-004SKILL-005SKILL-006
npx hackmyagent secure --ciLive = check implemented in hackmyagent; queued = declared, not yet implementedDefense (OASB Controls)
Live4 live · 0 queued
How to Cite
AI Agent Threat Matrix T-6004 (Skill/Plugin Backdoor). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-6004